Ask a simple question in most facilities, "where is the graded master for that spot", and you are really asking three or four different systems. The cloud bucket has its own console. The on-prem NAS has its own index. The LTO shelf answers only to a librarian. So the person doing the asking runs the same query in every place, stitches the answers together in their head, and hopes nothing important lived in the one store they forgot to check.
That is the real cost of a split estate. Not the storage bill, the search tax. Every media catalog search that has to be repeated per silo is an invitation to miss something, and the thing you miss is usually the file that would have saved you a re-shoot or a re-render. A media catalog search should return an answer, not a to-do list of other places to look.
Post and studio estates end up spread across storage tiers for good reasons. Hot work sits on fast disk. Warm libraries live on NAS or in the cloud. Anything old and heavy goes to tape, because nothing else in the building touches its cost per terabyte. The tiering is sound. What breaks is that each tier keeps its own catalog, so search across storage tiers becomes a manual relay instead of a single question.
The files never asked to be siloed. The catalogs did that. A camera master on tape and a working proxy on disk are the same shoot, but to your search tools they may as well be on different planets. Nobody planned that outcome, it accreted, one storage decision at a time, until the map of where things live lives only in a few senior people's heads.
Gateway is a read-only console over your whole media estate, and it treats every store, cloud, on-prem NAS and LTO tape, as something to read rather than something to migrate. A producer runs one query and gets results back from all of them together in a single set, each file returned with its checksum and its metadata. There is no separate "now search the archive" step, because the archive is no longer a separate destination, it is line items in the same answer as everything that is online.
That is the whole shift in one sentence: search across storage tiers stops being a workflow you perform and becomes a property of asking the question. You do not choose which silo to interrogate. You describe what you are looking for, and Gateway resolves it across the estate, checksums attached so you can prove two hits are the same bytes and not just the same filename.
Deep search finds files. The other half of Gateway is catalog Q&A: you point a question at a production and get a streamed answer about what exists and where it lives, tape included, without anyone handing out a mount command. It reads the same estate the file search does, so the answer covers cold storage as naturally as hot.
The part that matters to IT and security is how tightly this is governed. Permissions are resolved per question, so two people asking the same thing can legitimately get different answers based on what each is cleared to see. Every query writes an audit row, and the front door carries role-based access, authenticator-app MFA and single sign-on over OIDC and SAML 2.0. Nobody gets a firehose. Everybody gets exactly what their role permits, and the log remembers who asked what.
Note: Gateway is read-only by design, so a question can never change your data. Search and catalog Q&A only ever read the estate, and every one of them leaves a severity-tagged audit row you can export to your SIEM. When you actually need to write, ingesting new material or routing a delivery, that is Nexus, a separate product on an explicit, opt-in write path. Reading and writing stay cleanly apart, so a search can never move a byte by accident.
It would be easy to read "read-only" as a missing feature. It is the opposite. A console that can search everywhere but change nothing is safe to put in front of a whole building, because the worst outcome of a badly phrased query is a wrong answer, never a damaged archive. That is what lets a producer, a coordinator or a finance analyst all hold the same window into the estate without anyone worrying they will fat-finger a delete on the master.
It also keeps the trust model honest. The systems of record stay in charge of their own data. Gateway does not become a second copy you have to reconcile, it is a lens over what is already there. Combine that with per-question permissions and a full audit trail and you get something rare: broad visibility and tight control at the same time, instead of trading one for the other.
Describe the file or the question. Gateway resolves it across cloud, on-prem and tape in a single pass, no per-silo repeat.
Results come back as one set, every file carrying its checksum and metadata, permissions resolved per question so you see only what your role allows.
An audit row lands for each question, exportable to your SIEM, and nothing you asked ever changed a byte in any store.
Once a single query reaches every tier, a lot of quiet waste comes into view. Gateway also produces checksum-level duplicate detection reports and storage-cost reports across 8 storage tiers, priced on your own rates. When search can finally confirm that the expensive copy on fast disk is byte-identical to the one already on tape, you can retire the duplicate with a hash behind you, not a hunch. The visibility that fixes search is the same visibility that trims the storage bill.
And because the answer already spans the archive, judging a file before you restore it becomes practical. Pair Gateway with Lens, which previews about 140 formats in the browser with no restore and no pre-processing, and a reviewer can eyeball an archived candidate on screen before anyone queues a tape mount. Video previews are roughly 50x lighter in our tests, so scrubbing a proxy of an archived master does not mean pulling the master off tape at all. Search finds it, preview confirms it, and only then does the robot move once, for the right cartridge.
None of this asks you to consolidate storage or move anything. Gateway reads the cloud, NAS and tape catalogs you already maintain and presents them as one searchable surface. Your tiers stay tiered, your systems of record stay authoritative, and in production deployments the content stays in your environment. You are adding one honest window over the whole estate, not standing up another store to keep in sync.
The outcome is unglamorous and exactly what teams want: you ask where something is, and you get a straight answer that covers cloud, on-prem and tape at once, with checksums to prove it and a log to remember it. If you want to see that answer run against your own estate, that is what the four-week pilot produces. For the neighbouring pieces, our teams also read tape is a feature, not a graveyard and give your DAM a brain.